This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+8 more
Affected surfaces
ReleasePort's take
Moderate signalVersion v4.9.4 of Weechat patches a critical authentication bypass vulnerability and resolves several bug issues.
Why it matters: The release fixes an authentication bypass (severity 95) that could allow unauthorized access; all deployments using plain password hash authentication should upgrade immediately.
Summary
AI summaryUpdates core, logger, and https://github.com/weechat/weechat/security/advisories/GHSA-68ff-gq39-pqjm across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Patches authentication bypass with plain password hash algorithm Patches authentication bypass with plain password hash algorithm Source: llm_adapter@2026-07-19 Confidence: high |
— |
| Performance | Medium |
Improves speed of displaying long words in chat area Improves speed of displaying long words in chat area Source: llm_adapter@2026-07-19 Confidence: high |
— |
| Bugfix | High |
Fixes infinite loop when read_marker_string width is zero Fixes infinite loop when read_marker_string width is zero Source: llm_adapter@2026-07-19 Confidence: high |
— |
| Bugfix | High |
Fixes integer overflow in size calculation for ${hide:...} and ${base_encode:...} expansions Fixes integer overflow in size calculation for ${hide:...} and ${base_encode:...} expansions Source: llm_adapter@2026-07-19 Confidence: high |
— |
Full changelog
Fixed
Changed
- core: improve speed of display of long words in chat area (#2336)
Fixed
- core: fix infinite loop when option weechat.look.read_marker_string is set to a string with a width of zero (#2337)
- core: fix integer overflow in size calculation when evaluating "${hide:...}" and "${base_encode:...}" (#2335)
- logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators (#2340)
- relay: fix authentication bypass with the "plain" password hash algorithm (GHSA-68ff-gq39-pqjm)
Download
https://weechat.org/download/weechat/4.9.4/
Security Fixes
- GHSA-68ff-gq39-pqjm — relay authentication bypass with "plain" password hash algorithm
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]